Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.918exploits catalogados
38.248CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.505Exploit-DB 24.485GitHub PoC 15.786VulnCheck XDB 9182Nuclei 4448Metasploit 3512✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
E-topbiz Number Links 1 - 'id' SQL Injection
SQL injection vulnerability in admin/admin_catalog.php in e-topbiz Number Links 1 Php Script allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
SFS EZ Auction - Blind SQL Injection
SQL injection vulnerability in viewfaqs.php in Scripts for Sites (SFS) EZ Auction allows remote attackers to execute arb
23RIESGO
abrir ↗Referência✓ VexDay Proof
PNPHPBB2 < 1.2g - 'phpbb_root_path' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/functions_admin.php in PNphpBB 1.2g allows remote attackers to execu
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component live chat - SQL Injection / Open Proxy
SQL injection vulnerability in the Live Chat (com_livechat) component 1.0 for Joomla! allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP Blue Dragon CMS 2.9.1 - Cross-Site Scripting / SQL Injection Code Execution
SQL injection vulnerability in the GetModuleConfig function in public_includes/pub_kernel/pbd_modules.php in Php Blue Dr
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pie Cart Pro - 'Home_Path' Remote File Inclusion
PHP remote file inclusion vulnerability in enc/content.php in WAHM E-Commerce Pie Cart Pro allows remote attackers to ex
23RIESGO
abrir ↗Referência✓ VexDay Proof
paBugs 2.0 Beta 3 - 'main.php?cid' SQL Injection
SQL injection vulnerability in main.php in paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Referência✓ VexDay Proof
VWar 1.5.0 R15 - 'mvcw.php' Remote File Inclusion
PHP remote file inclusion vulnerability in convert/mvcw.php in Virtual War (VWar) 1.5.0 R15 and earlier allows remote at
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP 5.2.0 (Windows x86) - 'PHP_win32sti' Local Buffer Overflow
Buffer overflow in php_win32std.dll in the win32std extension for PHP 5.2.0 and earlier allows context-dependent attacke
23RIESGO
abrir ↗Referência✓ VexDay Proof
ImageStation - 'SonyISUpload.cab' 1.0.0.38 ActiveX Buffer Overflow
Buffer overflow in the Sony AxRUploadServer.AxRUploadControl.1 ActiveX control in AxRUploadServer.dll 1.0.0.38 in SonyIS
28RIESGO
abrir ↗Referência✓ VexDay Proof
VP-ASP 6.00 - 'shopcurrency.asp' SQL Injection
SQL injection vulnerability in shopcurrency.asp in VP-ASP 6.00 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
SFS EZ Career - SQL Injection
SQL injection vulnerability in content.php in Scripts For Sites (SFS) EZ Career allows remote attackers to execute arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
BasiliX 1.1.1 - 'BSX_LIBDIR' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in BasiliX 1.1.1 and earlier allow remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
Newswriter SW 1.4.2 - 'main.inc.php' Remote File Inclusion
PHP remote file inclusion vulnerability in include/main.inc.php in Sebastian Baumann and Philipp Wolfer Newswriter SW 1.
23RIESGO
abrir ↗Referência✓ VexDay Proof
Webmin 1.920 - Unauthenticated Remote Code Execution (Metasploit)
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir ↗Referência✓ VexDay Proof
AyeView 2.20 - '.GIF' Image Local Crash
AyeView 2.20 allows user-assisted attackers to cause a denial of service (application crash) via a GIF file with a malfo
23RIESGO
abrir ↗Referência✓ VexDay Proof
MyBlog: PHP and MySQL Blog/CMS software - SQL Injection / Cross-Site Scripting
Sam Crew MyBlog stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain se
23RIESGO
abrir ↗Referência✓ VexDay Proof
MKPortal 1.1.1 reviews / Gallery modules - SQL Injection
Multiple SQL injection vulnerabilities in MKPortal 1.1.1 allow remote attackers to execute arbitrary SQL commands via (1
23RIESGO
abrir ↗Referência✓ VexDay Proof
Netartmedia Blog System - SQL Injection
SQL injection vulnerability in image.php in NetArt Media Blog System 1.5 allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Referência✓ VexDay Proof
Vastal I-Tech Freelance Zone - 'coder_id' SQL Injection
SQL injection vulnerability in view_cresume.php in Vastal I-Tech Freelance Zone allows remote attackers to execute arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
WGCC 0.5.6b - 'quiz.php' SQL Injection
SQL injection vulnerability in quiz.php in Web Group Communication Center (WGCC) 0.5.6b and earlier allows remote attack
23RIESGO
abrir ↗Referência✓ VexDay Proof
vp-asp shopping cart 6.09 - SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in shopcustadmin.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote att
23RIESGO
abrir ↗Referência✓ VexDay Proof
HP-UX 11i - 'LIBC TZ' Enviroment Variable Privilege Escalation
Buffer overflow in the localtime_r function, and certain other functions, in libc in HP-UX B.11.11 and possibly other ve
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP Dir Submit - Authentication Bypass
Multiple SQL injection vulnerabilities in PHP Dir Submit (aka WebsiteSubmitter and Submitter Script) allow remote attack
23RIESGO
abrir ↗Referência✓ VexDay Proof
WEBBDOMAIN Webshop 1.02 - Authentication Bypass
SQL injection vulnerability in getin.php in WEBBDOMAIN WebShop 1.2, 1.1, 1.02, and earlier allows remote attackers to ex
23RIESGO
abrir ↗Referência✓ VexDay Proof
HP-UX 11i - 'swmodify' Local Stack Overflow / Local Privilege Escalation
Stack-based buffer overflow in the (1) swpackage and (2) swmodify commands in HP-UX B.11.11 and possibly other versions
23RIESGO
abrir ↗Referência✓ VexDay Proof
HP-UX 11i - 'swpackage' Local Stack Overflow / Local Privilege Escalation
Stack-based buffer overflow in the (1) swpackage and (2) swmodify commands in HP-UX B.11.11 and possibly other versions
23RIESGO
abrir ↗Referência✓ VexDay Proof
Vanilla 1.1.3 - Blind SQL Injection
Lussumo Vanilla 1.1.3 and earlier does not require admin privileges for (1) ajax/sortcategories.php and (2) ajax/sortrol
23RIESGO
abrir ↗Referência✓ VexDay Proof
Riddles Complete Website 1.2.1 - 'riddleid' SQL Injection
SQL injection vulnerability in riddle.php in Riddles Website 1.2.1 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Referência✓ VexDay Proof
MiniBB 2.0.2 - 'bb_func_txt.php' Remote File Inclusion
PHP remote file inclusion vulnerability in bb_func_txt.php in miniBB 2.0.2 and earlier, when register_globals is enabled
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.